Pgpool-II 中存在认证算法实现错误,这可能允许未经身份验证的攻击者将任意看门狗(watchdog)节点提升为领导者(leader)节点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II | 4.7.0 ~ 4.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92870 | 8.7 HIGH | Pgpool-II栈溢出致未认证进程终止漏洞 |
| CVE-2026-92867 | 8.7 HIGH | Pgpool-II越界写漏洞致代码执行 |
| CVE-2026-92871 | 8.7 HIGH | Pgpool-II空指针解引用致看门狗进程异常终止 |
| CVE-2026-92869 | 7.1 HIGH | Pgpool-II越界写漏洞致进程异常终止 |
| CVE-2026-92868 | 6.9 MEDIUM | Pgpool-II证书验证不当致认证绕过漏洞 |
| CVE-2026-92872 | 5.3 MEDIUM | Pgpool-II敏感信息泄露至日志文件漏洞 |
No comments yet